The MIT license, clear README, and only two runtime dependencies make the package easy to inspect and integrate. Its single-maintainer setup, absent security policy, and lack of repository security scanning leave little current support.
32%
Total Score
33
100
69
83
Only two releases were published, both in November 2016, with no releases in nearly 10 years. This is strong evidence of abandonment for a package intended as a maintained integration library.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with nearly 10 years without visible development. This materially raises abandonment risk.
Only one registry maintainer is listed. Because the repository is user-owned rather than organization-backed, this provides little redundancy if that maintainer stops supporting the package.
The repository is owned by an individual user, not an organization. This does not prove poor quality, but it offers less visible institutional backing when combined with the inactive history.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these counters provide no meaningful community cushion for the inactive project.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
evenement/evenement Version ^2.0 | — | — |
linecorp/line-bot-sdk Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.